Reflected Cross-Site Scripting Vulnerability in TranslatePress Plugin by WordPress
CVE-2026-17505
6.1MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 5 August 2026
What is CVE-2026-17505?
The TranslatePress plugin for WordPress is susceptible to a Reflected Cross-Site Scripting vulnerability due to improper handling of the 's' parameter. In versions up to and including 3.2.5, the translate_page() function replaces specific internal markers with unescaped angle brackets, enabling attackers to inject arbitrary scripts. This flaw allows unauthenticated users to execute harmful web scripts on affected pages, potentially compromising user interactions if a victim clicks on a manipulated link.
Affected Version(s)
TranslatePress β Translate Multilingual sites with AI Translation 0 <= 3.2.5